QUESTION 261
Which port or ports are used for the FTP data channel in passive mode?
A. random TCP ports
B. TCP port 21 on the server side
C. TCP port 21 on the client side
D. TCP port 20 on the server side
E. TCP port 20 on the client side
Answer: A
QUESTION 262
Why do firewalls need to specially treat an active mode FTP session?
A. The data channel is originating from a server side.
B. The FTP client opens too many concurrent data connections.
C. The FTP server sends chunks of data that are too big.
D. The data channel is using a 7-bit transfer mode.
Answer: A
QUESTION 263
Which statement is true about the TFTP protocol?
A. The client is unable to get a directory listing from the server.
B. The client is unable to create a new file on a server.
C. The client needs to log in with a username and password.
D. The client needs to log in using “anonymous” as a username and specifying an emailaddress as a password.
Answer: A
QUESTION 264
Which NTP stratum level means that the clock is unsynchronized?
A. 0
B. 1
C. 8
D. 16
Answer: D
QUESTION 265
Which statement is true about an NTP server?
A. It answers using UTC time.
B. It uses the local time of the server with its time zone indication.
C. It uses the local time of the server and does not indicate its time zone.
D. It answers using the time zone of the client.
Answer: A
QUESTION 266
Which four functionalities are built into the ISE? (Choose four.)
A. Profiling Server
B. Profiling Collector
C. RADIUS AAA for Device Administration
D. RADIUS AAA for Network Access
E. TACACS+ for Device Administration
F. TACACS+ for Network Access
G. Guest Lifecycle Management
Answer: ABDG
QUESTION 267
Which statement is correct about the Cisco IOS Control Plane Protection feature?
A. Control Plane Protection is restricted to the IPv4 or IPv6 input path.
B. Traffic that is destined to the router with IP optionswill be redirected to the hostcontrol plane.
C. Disabling CEF will remove all active control-planeprotection policies.
Aggregatecontrol-plane policies will continue to operate.?
D. The open-port option of a port-filtering policy allows access to all TCP/UDP basedservices that are
configured on the router.
Answer: C
QUESTION 268
Which Category to Protocol mapping for NBAR is correct?
A. Category: Enterprise Applications
Protocol: Citrix ICA, PCAnywhere, SAP, IMAP
B. Category: Internet
Protocol: FTP, HTTP, TFTP
C. Category: Network Management
Protocol: ICMP, SNMP, SSH, Telnet
D. Category: Network Mail Services
Protocol: MAPI, POP3, SMTP
Answer: B
QUESTION 269
Which two options correctly describe Remote Triggered Black Hole Filtering (RFC 5635)? (Choose two.)
A. RTBH destination based filtering can drop traffic destined to a host based on triggeredentries in the FIB.
B. RTBH source based filtering will drop traffic from a source destined to a host based ontriggered entries
in the RIB
C. Loose uRPF must be used in conjunction with RTBH destination based filtering
D. Strict uRPF must be used in conjunction with RTBH source based filtering
E. RTBH uses a discard route on the edge devices of the network and a routeserver to sendtriggered route
updates
F. When setting the BGP community attribute in a route-map for RTBH use the no- exportcommunity unless
BGP confederations are used then use local-as to advertise to sub- asconfederations
Answer: AE
QUESTION 270
A Cisco IOS router is configured as follows:
ip dns spoofing 192.168.20.1
What will the router respond with when it receives a DNS query for its own host name?
A. The router will respond with the IP address of the incoming interface.
B. The router will respond with 192.168.20.1 only if the outside interface is down.
C. The router will respond with 192.168.20.1.
D. The router will ignore the DNS query and forward it directly to the DNS server.
Answer: A
If you want to pass the Cisco 350-018 Exam sucessfully, recommend to read latest Cisco 350-018 Dumpfull version.